How to Install an ASA VPN (SSL) Certificate: Cisco ASA Training 101

  Рет қаралды 168,870

soundtraining.net

soundtraining.net

Күн бұрын

Пікірлер: 47
@abdumka
@abdumka 5 ай бұрын
Thanks for the well-documented video-can't believe I'm finding it 11 years after it was posted! Haha!
@professorfrank
@professorfrank Жыл бұрын
Awesome because the Cisco document is missing the export command
@doncrawley
@doncrawley Жыл бұрын
I'm glad it was helpful. Thanks for your comment.
@soundtraining
@soundtraining 11 жыл бұрын
Apologies for the delayed reply. The FQDN is how the device is identified via its certificate. It doesn't require a DNS A record, but without an A record or an entry in a local hosts file, there would be no point in having the certificate to prove name-based identity. I've never used an IP address with a certificate, but I don't know why it wouldn't work. In fact, there are some CAs that offer that service. Obviously, that would eliminate the need for either an A record or a hosts file entry.
@soundtraining
@soundtraining 11 жыл бұрын
The CA certificate is generated by the device you wish to configure as a certificate authority, such as a Windows Server 2012 computer or a Linux computer. The certificate can either be self-signed or signed by an upstream certificate authority such as Verisign, Comodo, GeoTrust, or any of the many other CAs. If you visit any of the CA websites, you'll find more information about the process.
@tompinkerton8099
@tompinkerton8099 3 жыл бұрын
Excellent video! It helped me out immensely.
@soundtraining
@soundtraining 11 жыл бұрын
It's been a while, but I think I got that one from DigiCert. You can get trial certs from lots of providers and most of them should work similarly to what you see in the video.
@georgiev85
@georgiev85 11 жыл бұрын
So for the "Certificate Subject DN": - does the FQDN need to have an A record in DNS? - can we use an IP instead? I guess I am not sure what the FQDN is used for in this case.
@Breto151
@Breto151 11 жыл бұрын
So just to make sure I have this right you got both certs from Digicert? I have been trying to setup my own Windows 2008 CA to do a similar VPN design. I wasn't sure if the 2nd cert was from Digicert or it was created from something else that I missed.
@brandonfontaine285
@brandonfontaine285 2 жыл бұрын
How is this done without ASDM? My CF card cannot hold asa and asdm image
@cloudwaf-fbi
@cloudwaf-fbi 3 жыл бұрын
very good,good job
@ismailrajaallah1667
@ismailrajaallah1667 11 жыл бұрын
hi can you tell me how to have a ca certificate
@Breto151
@Breto151 11 жыл бұрын
Where did you get the ASA_soundtraining cert from?
@heraldsison5410
@heraldsison5410 5 жыл бұрын
Hi Sir, i have encountered a problem when installing certificate. i have already generated CSR and comodo already replied to us the certificate, i have also uploaded the CA certificate that comodo gave us. but when i try to install the cert in identity certificate the "Install Button" is greyed out. How can i fix this sir? i really want this to be done within today but i am stucked to this portion, i have attached a screenshot for your reference. Thank you so much, Your reply is much appreciated.
@branimirkarajcic7839
@branimirkarajcic7839 11 жыл бұрын
What is the purpose of that default key that is generated? I would think it is because of SSH, but it is not since to get SSH to work it is still needed to generate RSA key.
@rohanacharekar92
@rohanacharekar92 8 жыл бұрын
Hi Don thanks a lot for the video. Just wanted to know if you have uploaded the following video on how to associate the certificate with the remote access vpn ??????
@muriloninja
@muriloninja 7 жыл бұрын
Remote Access VPN->Advanced->SSL Settings...then assign it to the Outside interface, it will show up in a list there once you highlight the interface and click edit.
@immenseTie
@immenseTie 7 жыл бұрын
Can I plz get a answer also.....has the next video been released... associate certificate with the remote access vpn
@malcontentman9820
@malcontentman9820 7 жыл бұрын
When going to install the asa01_soundtraining_crt cert, how was that generated? I think I am missing a step. Many thanks!
@ishanmishra4386
@ishanmishra4386 10 жыл бұрын
i have received 2 certificated from my CA..intermediate & ssl certificate..which certificate should i install in identity certificate & which one should i install in CA..
@timbatec
@timbatec 10 жыл бұрын
is there any easier way to validate that certificate?
@RaissaMarconConstante
@RaissaMarconConstante 9 жыл бұрын
Hi, excellent video! Could you publish the commands used behind ASDM to install the certificate? I'd really like to know the commands. Thank you!
@soundtraining
@soundtraining 9 жыл бұрын
+Raissa Marcon Constante My apologies for the delay in responding. I just now noticed your question. In the ASDM, there is an option to preview commands. Look under Tools>>Preferences>>General.
@mghebremichael
@mghebremichael 8 жыл бұрын
Hello,I am wondering if I can use VPN Digital Certificate on my Both ISP interfaces.... do I need to generate key for each ISP interface?
@AngyOtt
@AngyOtt 9 жыл бұрын
Do you need a certificate to perform in-class exercise with VPN?
@soundtraining
@soundtraining 9 жыл бұрын
+Paul Kim Older versions of the software did not require a certificate. I couldn't find a way around it in version 9.x. For demonstrations, I either get a trial certificate or set up a certificate server and generate my own. Thanks for your questions.
@AngyOtt
@AngyOtt 9 жыл бұрын
running ASA 832 (can't recall perfectly) so IPSEC/Anyconnect VPN should work just fine, right? Thank you for your answers :D
@mudslide135
@mudslide135 11 жыл бұрын
So I generate the key then go to entrust and paste the csr and it keeps giving me the error -null is not a lid country code...what does this mean? Would it be related to not having my home network on a configured domain. Just bough the the asa and am trying to set it up to play around with at home
@xphobe
@xphobe 9 жыл бұрын
+Justin C (K1m0ra) You have to have a valid public DNS domain name associated with the public outside IP of your ASA. You can get one free from dyndns.org, which has the added benefit of being able to track your IP even if you get one via DHCP from your isp, and keeping your domain name registered to it.
@Asianredneck1000
@Asianredneck1000 9 жыл бұрын
I saw that he saved the self generated as a TXT file not as a CRT. Do I go back and save the file as a crt? I did not see where he saved the asaol.soundtraining.net.crt certificate. Little confused where he got that asao1.soundtraining.crt file from. Was that from digicert? Anyone can help?
@xphobe
@xphobe 9 жыл бұрын
+Tyson Vu Yes, he got it from digicert. Remember, he got two: the intermediate or chain cert file, and also the identity cert file. When he installed each one, he browsed to where he had saved the files. He did mention that you cannot see the extension, but it is .crt.
@phuckewe178
@phuckewe178 9 жыл бұрын
I get a message that reads WARNING you already have a RSA key name Default ASA Key. Is this different than the SSL certificate we're generating?
@soundtraining
@soundtraining 9 жыл бұрын
+Phuck Ewe No, the message means you're replacing the default key. You don't actually have to generate a new default key, but I wanted to show the process for generating a key. I just did it that way for the demonstration. Sorry I wasn't more clear about that in the video.
@rachidfa6376
@rachidfa6376 8 жыл бұрын
I have an ASA 5510 Version 8.2 (5) with the following config Hardware: ASA5510 1024 MB RAM, CPU Pentium 4 Celeron 1600MHz Internal ATA Compact Flash, 256MB my question I want to install Annyconnect vpn with this config. is that it is compatible with the prerequisites to install annyconnect with 256mb flash?Maximum Physical Interfaces : Unlimited Maximum VLANs : 100 Inside Hosts : Unlimited Failover : Active/Active VPN-DES : Enabled VPN-3DES-AES : Enabled Security Contexts : 2 GTP/GPRS : Disabled SSL VPN Peers : 2 Total VPN Peers : 250 Shared License : Disabled AnyConnect for Mobile : Disabled AnyConnect for Cisco VPN Phone : Disabled AnyConnect Essentials : Disabled Advanced Endpoint Assessment : Disabled UC Phone Proxy Sessions : 2 Total UC Proxy Sessions : 2 Botnet Traffic Filter : Disabled thank you
@kelloggfan
@kelloggfan 10 жыл бұрын
following your every move - you make it look easy but for 2 days I am getting the following error: Cannot import certificate - Certificate does no contain device's General Purpose public key for trust point ......ERROR: Failed to parse or verify imported certificate. What could be wrong - I am following exactly every move...??
@soundtraining
@soundtraining 10 жыл бұрын
Which ASA software version are you running?
@kelloggfan
@kelloggfan 10 жыл бұрын
soundtraining.net I am running 8.2(5) ASDM 7.1(6)
@soundtraining
@soundtraining 10 жыл бұрын
William Rossetti William, that's a really old version of the ASA software. The video is based on version 9.11. If you can't upgrade, check out the Cisco documentation at www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/cert_cfg.html
@kelloggfan
@kelloggfan 10 жыл бұрын
so are you saying the older version won't work?
@soundtraining
@soundtraining 10 жыл бұрын
soundtraining.net Not at all. What I'm saying is that the video is based on software version 9.11 and you're working with version 8.25. There are probably differences in the commands and it's been a long time since I've worked with version 8.25, so I don't remember the syntax for that version. That's why I posted the link where you could get the correct syntax for the version you're using.
@minhtruong6935
@minhtruong6935 12 жыл бұрын
love it...thanks
@mayankdhingra4086
@mayankdhingra4086 8 жыл бұрын
font size is very small very diffult to see the configuration
@raghavanaidu7867
@raghavanaidu7867 9 жыл бұрын
PLZZ EXPLAIN THEORY FIRST
How to Configure an ASA VPN Split-Tunnel: Cisco ASA Training 101
10:37
soundtraining.net
Рет қаралды 56 М.
Cisco ASA AnyConnect Remote Access VPN Configuration: Cisco ASA Training 101
15:42
Леон киллер и Оля Полякова 😹
00:42
Канал Смеха
Рет қаралды 4,7 МЛН
Каха и дочка
00:28
К-Media
Рет қаралды 3,4 МЛН
Enceinte et en Bazard: Les Chroniques du Nettoyage ! 🚽✨
00:21
Two More French
Рет қаралды 42 МЛН
Гениальное изобретение из обычного стаканчика!
00:31
Лютая физика | Олимпиадная физика
Рет қаралды 4,8 МЛН
How to Become a Tech Professional
2:46:10
Eli the Computer Guy
Рет қаралды 1,5 М.
LabMinutes# SEC0116 - Cisco SSL VPN ASA Certificate Install
17:45
Cisco ASA 5505 Firewall Initial Setup:  Cisco ASA Training 101
26:59
soundtraining.net
Рет қаралды 605 М.
Cisco ASA Certificate Setup for AnyConnect VPN
1:26:53
Sunset Learning Institute
Рет қаралды 23 М.
IPSec Site to Site VPN tunnels
18:44
Keith Barker - The OG of IT
Рет қаралды 498 М.
How to Setup a Cisco Router VPN (Site-to-Site):  Cisco Router Training 101
15:12
How to create a valid self signed SSL Certificate?
25:01
Christian Lempa
Рет қаралды 381 М.
Леон киллер и Оля Полякова 😹
00:42
Канал Смеха
Рет қаралды 4,7 МЛН